Sanctions Compliance Is Changing: From Name Screening to Network Detection
Recent sanctions developments provide an important reminder for financial institutions: sanctions compliance can no longer be treated primarily as a screening exercise.
8/27/20265 min read


The latest U.S. measures against Iran illustrate the direction clearly. On August 24, 2026, the U.S. Treasury launched Operation Economic Outcast, targeting Iranian revenue, sanctions-evasion and financial networks. Treasury specifically highlighted digital assets, technology and other economic channels used to generate revenue and circumvent restrictions.
At almost the same time, U.S. authorities moved in the opposite direction on Syria. The State Department rescinded Syria's designation as a State Sponsor of Terrorism and revoked the Specially Designated Global Terrorist designation of Hay'at Tahrir al-Sham (HTS), while OFAC removed HTS from the SDN List. However, authorities simultaneously designated two former HTS affiliates for continuing links to al-Qa'ida and Hurras al-Din.
Together, these developments demonstrate something increasingly important for compliance professionals:
Sanctions risk is dynamic. It involves not only who is on a list, but networks, ownership, behaviour, geography, products, intermediaries and the mechanisms used to move value.
FATF is increasingly focused on sanctions evasion
This direction is strongly reinforced by the Financial Action Task Force.
FATF's report Complex Proliferation Financing and Sanctions Evasion Schemes identifies significant weaknesses in the international financial system's ability to detect and disrupt proliferation financing and sanctions evasion.
The report identifies four particularly important methods:
use of intermediaries to circumvent sanctions;
concealment of beneficial ownership;
use of virtual assets and other technologies;
exploitation of maritime and shipping networks.
These are significant because none necessarily produces a simple sanctions-list match.
A company may therefore screen successfully against an SDN or UN list and still facilitate sanctions evasion.
The real question becomes:
Who ultimately owns, controls, finances or benefits from the transaction?
Recommendation 7 is becoming increasingly important
FATF Recommendation 7 requires countries to implement targeted financial sanctions associated with UN Security Council resolutions addressing proliferation of weapons of mass destruction and its financing. FATF also expects jurisdictions to identify and assess risks involving breaches, non-implementation or evasion of proliferation-related targeted financial sanctions and adopt measures proportionate to those risks.
That distinction matters.
Traditional sanctions compliance often asks:
Is this customer or counterparty sanctioned?
A proliferation-financing risk approach requires additional questions:
Could this transaction be helping somebody circumvent sanctions?
Could the stated customer be acting for another party?
Does the trade route make economic sense?
Why was an intermediary company inserted into the transaction?
Does the beneficial ownership structure obscure the real party involved?
This is much closer to financial-crime investigation than conventional name screening.
MENAFATF puts targeted financial sanctions under regional scrutiny
The Middle East and North Africa Financial Action Task Force has also made targeted financial sanctions a specific area of work.
In April 2026, MENAFATF published its study Implementation of Targeted Financial Sanctions in the Region, designed to help member countries strengthen legal, operational and supervisory mechanisms and improve the effectiveness of TFS implementation.
Its work is particularly relevant given the importance of the Middle East to current sanctions regimes involving Iran, terrorist financing and proliferation financing.
MENAFATF's recent programme has also included work on implementation tools and sanctions-evasion methods. Its latest annual reporting identifies guidance on implementing targeted financial sanctions and combating sanctions evasion among its key technical work.
The message is important: having sanctions legislation is not enough. Regulators increasingly want evidence that institutions can identify attempts to circumvent it.
MONEYVAL: virtual assets create another sanctions-evasion channel
The Council of Europe's MONEYVAL has reached similar conclusions from another direction.
Its February 2026 report examining virtual assets across MONEYVAL jurisdictions specifically identifies their potential misuse for sanctions evasion and proliferation financing, alongside money laundering, terrorist financing and fraud. MONEYVAL also highlights weaknesses in data collection and visibility into cross-border virtual-asset flows.
That matters because virtual assets allow value to move outside conventional correspondent-banking chains.
For sanctions teams, therefore, understanding crypto exposure increasingly becomes part of understanding the customer's overall sanctions risk—even when the institution itself does not directly provide cryptocurrency services.
MONEYVAL evaluations show what effectiveness looks like
Recent MONEYVAL country assessments provide another indication of where supervision is heading.
Its July 2026 evaluation of Armenia found well-functioning proliferation-financing coordination and generally sound understanding of PF risks, including links with PF-hub jurisdictions and sanctions-evasion typologies. But MONEYVAL also found that understanding of sanctions evasion was less mature outside banking and that supervision of non-bank financial institutions and DNFBPs remained more limited.
Romania's July 2026 follow-up report similarly examined improvements to technical compliance involving targeted financial sanctions for both terrorist financing and proliferation financing.
These assessments reinforce an emerging principle:
Screening capability is only one component of sanctions effectiveness.
The convergence of AML, sanctions and trade controls
This is perhaps the most important development for financial-crime professionals.
Historically, institutions often maintained relatively separate programmes:
AML | sanctions | export controls | fraud | trade finance
Modern sanctions-evasion networks do not respect those organizational boundaries.
A single investigation can involve:
shell company → hidden beneficial owner → third-country intermediary → unusual trade route → dual-use goods → cryptocurrency settlement → sanctioned end user.
The FATF typologies increasingly reflect exactly this kind of interconnected structure.
That means financial institutions need to become better at connecting information that may currently sit in different systems or different teams.
What financial institutions should be doing now
The practical response should extend well beyond refreshing sanctions lists.
Institutions should consider whether their financial-crime frameworks can identify indirect exposure and circumvention, particularly involving:
Beneficial ownership. Who ultimately owns or controls companies involved in the transaction?
Intermediaries. Why has an apparently unnecessary company, bank or jurisdiction entered the payment chain?
Trade routes. Does the movement of goods correspond with the customer's normal commercial activity?
Shipping. Are vessels, ownership structures, flag changes or routing patterns unusual?
Virtual assets. Is cryptocurrency being used to introduce or remove transparency from payment flows?
Technology and dual-use goods. Could apparently ordinary commercial products ultimately support restricted military or proliferation activities?
Behavioural change. Did a customer restructure transactions immediately after sanctions were introduced?
These are increasingly sanctions questions as much as AML questions.
Sanctions relief creates compliance risk too
The recent Syria action illustrates another side of the problem.
Removing a person or organization from a sanctions regime does not mean institutions should automatically treat every associated relationship as low risk.
OFAC's August 24 action removed restrictions applicable to HTS while simultaneously targeting former affiliates who continued supporting terrorist organizations. Transactions with HTS no longer require OFAC authorization solely because of its former designation, but other blocked persons and prohibited activities remain subject to restrictions.
Institutions therefore need effective processes for both:
sanctions escalation and sanctions de-escalation.
Failing to remove obsolete restrictions creates unnecessary de-risking and financial exclusion. Removing controls too broadly can expose institutions to remaining terrorist-financing or sanctions risks.
The next generation of sanctions compliance
The direction emerging from FATF, MENAFATF and MONEYVAL is increasingly clear.
The first generation of sanctions compliance was largely about lists.
The next generation is about networks.
Effective sanctions programmes will increasingly need to combine:
screening + beneficial ownership + transaction monitoring + trade analysis + network analytics + geographic risk + virtual-asset intelligence + investigative judgment.
The objective is no longer simply to answer:
“Is this person sanctioned?”
The more important question is:
“Could this customer, transaction or corporate structure be helping someone circumvent sanctions?”
That is a substantially more difficult question but it is increasingly the question regulators and FATF-style bodies expect financial institutions to be capable of answering.
Subscribe to our newsletter
Stay current in Anti Financial Crime Compliance
Contact us
amltraining@zoho.com
© 2026. All rights reserved.
